Home Messaging

Below are the M3AAWG published materials related to our messaging anti-abuse work. There is also a Messaging video playlist on our YouTube channel at www.youtube.com/maawg and there are a few selected videos on our website in the Training Videos and Keynotes Videos sections under the Meetings menu tab.

Best Practices

PDF
March 01, 2018

M3AAWG Compromised User ID Best Practices, Version 1.0.1

Updated in March 2018, this document addresses problems associated with compromised user accounts. It discusses mitigation techniques and methods of identifying compromised accounts, including recommendations to ensure the long-term security of accounts to prevent “re-compromise.”

PDF
February 28, 2018

M3AAWG Help – I’m On A Blocklist, version 1.0.1

Nearly all email systems, including those of Email Sender Providers and network operators, at some point have delivery issues because their sending IPs or domains are on a blocklist. This document shares established procedures defining how to triage and respond to a blocklisting to assist in a timely and effective resolution.  Version 1.0.1 was updated in February 2018.

PDF
January 31, 2018

M3AAWG Recommendations for Preserving Investments in New Generic Top-Level Domains (gTLDs)

Over a thousand new generic Top-Level Domains (gTLDs) have been, or are in, the process of being created under ICANN’s new gTLD program.  This paper is written for current Registry operators and for companies interested in applying for new gTLDs, and outlines the risks and some relatively simple recommendations that can help correct these problems.

PDF
December 30, 2017

M3AAWG Recommendations for Senders Handling of Complaints

Email abuse rates can significantly affect a sender’s reputation and, consequently, its ability to deliver customers’ emails to the inbox. This paper explains some of the common processes senders can use to effectively manage and monitor email complaints and to help their customers, who are the list owners, develop healthy email practices that generate better results.
of email lists.

PDF
November 03, 2017

M3AAWG Recommendation on Web Form Signup Attacks

Many list web forms provoke an email confirmation to the subscriber's email address provided in the form but malicious entities are now using this feature to do bulk form submissions with forged addresses that flood the subscriber’s inbox. M3AAWG members collaborated across the industry to propose a header as an initial step that hosting and sending companies can implement to help protect against these attacks. The header allows receivers to identify floods of mail coming from sign-up forms that are bombarding victim mailboxes.

Pages

Public Policy Comments

September 26, 2014

Comments on Implementation of CSRIC III Cybersecurity Best Practices

M3AAWG submitted these comments with the new M3AAWG Bot Metrics Report in response to the U.S, Federal Communications Communications request for comments on the status of the implementation of CSRIC III best practices.

August 04, 2014

Additional Responses from Dr. Paul Vixie to the U.S. Senate Hearing on "Taking Down Botnets: Public and Private Efforts to Disrupt and Dismantle Cybercriminal Networks"

Dr. Vixie's August 4th written response to additional questions requested after the hearing on botnet takedowns is also available from the official U.S. Committee on the Judiciary Committee hearing website at
www.judiciary.senate.gov/download/vixie-qfrs-71514 .

December 01, 2013

M3AAWG Comments on ICANN Misuse Report

Submitted to ICANN in December 2013 in response to ICANN's misuse survey.

August 12, 2013

M3AAWG Comments on ICANN EWG Initial Report

Submitted to ICANN in August 2013 in response to ICANN's Expert Working Group report.

July 31, 2013

M3AAWG Response to CWG-Internet Request for Online Consultation-Combatting Spam

Submitted to the ITU Council Working Group on International Internet–Related Public Policy Issues (CWG–Internet) in July 2013
In response to a request for comments on effectively countering and combatting spam.

Pages

M3AAWG Reports

DM3Z Blog

Updates and Commentary from the Messaging, Malware and Mobile Anti-Abuse Working Group

None at this time.

News

Articles About M3AAWG

URL
October 25, 2018

How Do You Fight a $12B Fraud Problem? One Scammer at a Time

https://krebsonsecurity.com/2018/10/how-do-you-fight-a-12b-fraud-problem...

Brian Krebs interviewed Ronnie Tokazowski, founder of the private BEC List that received the 2018 JD Falk Award, on Business Email Compromise and the list's cooperative fight to protect end-users. 

PDF
October 09, 2018

Group recognized for efforts thwart Nigerian email scams

https://thehill.com/policy/cybersecurity/410603-private-group-recognized...

Coverage of the BEC List fighting online fraud and the M3AAWG 2018 JD Falk Award it received.

URL
June 20, 2018

The History of Email with Dave Crocker, Part 2

 

https://thenetworkcollective.com/2018/06/hon-email-part-2/

In 1990, an unresolvable debate over how to expand email beyond ASCII text spawned two separate working groups and is a rare example of how staunchly competitive tech groups unintentionally ended up collaborating to create something important that went beyond the original objective. The result: multimedia email, according to M3AAWG Senior Technical Advisor Dave Crocker in part 2 of his Network Collective podcast on the history of email.

PDF
November 13, 2017

Hackers Shut Down ProPublica’s Email For a Day. Here’s How to Stop Attacks Like That.

ProPublica's Julia Angwin augments her earlier "list bomb" article with information on what can be done to prevent these attacks. 

PDF
November 09, 2017

How Journalists Fought Back Against Crippling Email Bombs

https://www.wired.com/story/how-journalists-fought-back-against-cripplin...

Wired Magazine published ProPublica's journalist Julia Angwin account of how she and colleages were "list bombed" and talks about the growing problem, including a preventive strategy developed by M3AAWG.
 

Pages

Subscribe to